I have a product off site that needs to get LDAP information from my domain controller. I have the firewall open, and he is able to connect on regular LDAP ...
I never tried this but, if I where in your shoes, I'd pull a copy of Wireshark, instruct it to use the SSL dissector on TCP 636 and have a look at a packet dump: if you're looking at an SSL failure, ...